Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 211

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Trump administration equity stakes pose risks to U.S. companies and markets
voice message by recording in question area
Nearly a thousand Google workers sign letter urging company to divest from ICE, CBP
Couple bought a 140-year-old New Jersey home for $550,000 and spent $172,000 renovating it—take a look inside
I've studied over 200 kids—the happiest ones have parents who do 6 things with them before bedtime
Pressure mounts on American Airlines CEO as carrier lags rivals
Trump’s 'big beautiful bill' may spur significant changes to higher education in 2026 and the rise of 'un-college,' experts say
Top Wall Street analysts like these stocks for long-term growth potential
Elon Musk wants to be a trillionaire — here's how SpaceX may get him there
U.S. plans initial payment towards billions owed to the UN, envoy Waltz says